By NHI Mgmt Group Editorial TeamBased on Axiad: “Three Authentication Predictions for 2024” (September 16, 2025)

TL;DR: Phishing, stolen passwords, and account recovery abuse are converging with generative AI to make authentication attacks easier and more effective, according to Axiad and the cited Verizon and FIDO findings. Passwordless and phishing-resistant MFA help, but recovery workflows are now the softer target.


At a glance

What this is: Axiad argues that authentication risk is moving from password capture toward account recovery abuse, with generative AI amplifying phishing and recovery-path exploitation.

Why it matters: IAM teams have to treat recovery workflows as an authentication surface, because strengthening the login screen does not close the easier path into identity compromise.

By the numbers:

  • 74% of breaches involve the human element, according to Verizon’s 2023 Data Breach Investigations Report cited by Axiad.
  • The two primary ways attackers access an organisation are stolen passwords at 50% and phishing at 15%, according to Verizon’s 2023 Data Breach Investigations Report cited by Axiad.
  • Passwords are the root cause of 80% of data breaches, according to the FIDO Alliance cited by Axiad.

Context

Authentication risk is shifting because attackers do not need to break the strongest visible control when a weaker recovery path remains open. Passwordless and phishing-resistant MFA improve the front door, but the recovery process can still expose help-desk workflows, knowledge-based questions, and social-engineering opportunities.

This matters for IAM because authentication is no longer just about login events. Recovery flows, account reset procedures, and support interactions now sit inside the identity attack surface and can bypass otherwise strong primary authentication.

Generative AI lowers the cost of believable phishing and makes attacker reconnaissance more effective. That changes the economics of account takeover, especially where recovery depends on information that can be assembled from public sources or previous breaches.


Key questions

Q: How should organisations implement passwordless IAM without weakening recovery controls?

A: Treat passwordless as an assurance program, not a user-experience feature. Enrolment, device binding, biometrics, and fallback recovery must be governed together so the reset path is not easier to abuse than the primary login path. The strongest deployments define recovery thresholds, step-up checks, and auditability before rollout.

Q: Why do passwordless programmes still get compromised through recovery paths?

A: Because passwordless improves the login step, not every way identity is re-established. If users or help desks can reset access through weaker questions, informal validation, or alternate channels, attackers will target those paths instead of the primary factor.

Q: What are the signs that account recovery is the weakest part of authentication?

A: Common signs include heavy help-desk involvement, reliance on knowledge-based questions, inconsistent verification steps, and recovery channels that differ from primary authentication policy. Those patterns usually indicate the fallback path is easier to exploit than the front door.

Q: How should organisations adapt security awareness training for generative AI phishing?

A: Security teams should move from static annual training to continuous, behaviour-focused reinforcement. Use short exercises, phishing simulations, reporting drills, and manager-supported reminders that train employees to verify requests through a second channel. The goal is not perfect detection of every message. It is faster hesitation, better escalation, and fewer successful credential captures.


Technical breakdown

Why account recovery becomes the weak link in passwordless programmes

Passwordless authentication removes one attack surface, but it does not remove the identity proofing problem behind account recovery. If a user forgets a factor, loses a device, or is locked out, the organisation must re-establish trust before issuing access again. That step often relies on help desks, knowledge-based questions, or alternate email and phone channels. Those paths are operationally useful but security-sensitive because they reintroduce shared knowledge and human judgement into a process that was supposed to be stronger than passwords. The control question is not whether login is resistant, but whether recovery is equally resistant to social engineering and impersonation.

Practical implication: review recovery workflows as authentication controls, not as support processes.

How generative AI changes phishing economics

Generative AI makes phishing more scalable because it improves language quality, context, and targeting at near-zero marginal cost. That matters because many traditional user cues, such as poor grammar or obvious formatting mistakes, are no longer reliable indicators of fraud. Attackers can also blend public details from social media or corporate sites into messages that fit the recipient’s environment. The result is not simply more phishing, but phishing that is harder to triage by eye and easier to automate at volume. This raises the baseline risk for both password capture and recovery abuse, because the same social-engineering channel can be used to gather the information needed for both.

Practical implication: assume phishing content quality is no longer a dependable detection signal.

Passwordless plus means closing the recovery loop

A passwordless model only becomes materially stronger when recovery is redesigned with the same level of assurance as primary authentication. Otherwise, the organisation has replaced a weak front door with a stronger one while leaving the side entrance open. Modern recovery should minimise reusable knowledge, reduce support-agent discretion, and rely on high-assurance verification methods that are consistent with the initial authentication policy. In governance terms, the issue is not the absence of password entry alone. It is whether the organisation can re-establish identity without creating a lower-assurance exception path that attackers can predict, probe, and exploit.

Practical implication: align recovery assurance with the strength of the primary authentication method.


Threat narrative

Attacker objective: The attacker wants to compromise identity through the weakest authentication path and take over the account without defeating passwordless controls directly.

  1. Entry begins with AI-assisted phishing or support impersonation that targets a user or help desk channel rather than the primary login screen.
  2. Credential or recovery data is harvested through social-engineered responses, public-source profiling, or knowledge-based prompts that reveal enough to satisfy reset checks.
  3. The attacker uses the recovery workflow to reset access, bypass strong primary authentication, or replace the user’s protected credentials with attacker-controlled ones.
  4. Impact is account takeover through the less protected recovery path, which can lead to further fraud, data access, or internal impersonation.
  • Co-op cyber attack 2025: Attackers linked to Scattered Spider tricked their way into a Co-op employee account and stole personal data of all 6.5 million members.
  • SonicWall SSL VPN account compromises 2025: Attackers used valid credentials to log in to more than 100 SonicWall SSL VPN accounts across 16 environments in October 2025.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Account recovery is now part of the authentication perimeter: Passwordless adoption does not eliminate authentication risk; it relocates it. The organisation still has to prove identity when users lose access, and that proving step is often weaker than the login step it replaces. The implication is that IAM governance must treat reset, recovery, and help-desk approval as first-class authentication controls, not operational exceptions.

Generative AI collapses the old phishing-detection assumptions: Security programmes built around spotting poor grammar or generic lures are already behind. When attackers can generate context-rich, believable messages at scale, the distinguishing feature is no longer message quality but the trust boundary behind the response. Practitioners should assume social engineering has become cheaper, faster, and more convincing across both human and support-channel attacks.

Modern account recovery needs assurance symmetry: The security of a passwordless programme is determined by its weakest alternate path. If recovery can be completed with lower assurance than initial authentication, the architecture invites a downgrade attack through process design rather than technical compromise. The field needs to measure recovery with the same rigor used for authentication policy and identity proofing.

Recovery path trust debt: Organisations accumulate trust debt when they modernise the login experience but leave legacy recovery channels untouched. That debt shows up as help-desk discretion, knowledge-based verification, and fallback channels that attackers can predict from public data. Practitioners should treat this as an architectural debt item, not a user-support inconvenience.

Passwordless plus is a governance test, not a product category: The article’s real signal is that authentication maturity now depends on the entire identity journey, from enrolment through recovery to reproofing. The next control gap will not be the absence of a password, but the presence of a weaker recovery path that undermines the new model. Teams should evaluate whether their recovery design matches their stated authentication assurance level.

What this signals

Recovery path trust debt: Passwordless adoption only pays off when the fallback path is rebuilt to the same assurance level as the primary one. If account recovery still depends on human judgement, shared knowledge, or easily researched personal data, attackers will treat it as the preferred entry point.

Generative AI changes the threat model by making phishing cheaper to produce and harder to spot, which increases pressure on both users and help desks. IAM leaders should expect the operational burden to move from password theft to proof-of-identity failure at the recovery boundary.


For practitioners

  • Strengthen account recovery assurance Require recovery methods that match the assurance level of the primary authentication policy and remove low-trust fallback paths such as easily guessed knowledge questions.
  • Redesign help desk verification Limit support-agent discretion in reset workflows and replace informal verification steps with auditable, policy-driven recovery checks.
  • Harden phishing-resistant MFA Use phishing-resistant MFA for primary sign-in so recovery abuse cannot be paired with weak login controls to complete account takeover.
  • Map social-engineering exposure points Identify where attackers can gather recovery data from public sources, support scripts, or alternate channels, then reduce those disclosure paths.
  • Review fallback authentication paths Test what happens when the primary factor is unavailable and verify that the fallback path does not lower assurance below policy.

Key takeaways

  • The core problem is no longer just stolen passwords, but weaker recovery paths that can bypass stronger sign-in controls.
  • Generative AI makes phishing more convincing and more scalable, which increases the value of social engineering against users and support teams.
  • Organisations should align recovery assurance with passwordless authentication strength so the fallback path does not become the easiest route into the account.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-63 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article focuses on weak authentication and recovery paths that enable account takeover.
NHI-10 — Human Use of NHIHelp-desk and recovery workflows depend on humans validating identity and can be socially engineered.
Recommendation — Review authentication and recovery flows under NHI-04 and remove low-assurance fallback methods. Limit human-mediated recovery steps that attackers can manipulate through social engineering.
NIST SP 800-63SP 800-63B — AuthenticationThe article is about authentication assurance and recovery in passwordless environments.
Recommendation — Apply SP 800-63B to align recovery and authenticator assurance with the primary sign-in method.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsRecovery paths can reissue access outside intended authorisation boundaries.
Recommendation — Use PR.AA-05 to ensure recovery does not grant access beyond policy.
MITRE ATT&CKTA0006 — Credential AccessThe threat pattern centers on stealing or resetting credentials through phishing and recovery abuse.
Recommendation — Map recovery abuse to TA0006 and monitor for credential-harvesting and reset attempts.

Key terms

  • Account Recovery: Account recovery is the process used to restore access when a user cannot authenticate normally. In mature IAM programmes, recovery is treated as part of the trust chain because a weak reset path can bypass stronger login controls and become the easiest route to account takeover.
  • Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
  • Phishing-Resistant MFA: Phishing-resistant MFA uses authentication factors that cannot be easily replayed, intercepted, or socially engineered. In regulated environments, this usually means device-bound or cryptographic methods rather than push prompts or SMS codes, because the control must hold up under realistic attack conditions.
  • Recovery Assurance: The level of confidence that an organisation has in identity proofing during password reset, device replacement, or account recovery. Strong recovery assurance is essential because the overall security of an authentication system is limited by the least trustworthy path back into the account.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org